Master Privacy Policy for Kutor Labs Browser Extensions
Last Updated: September 9, 2026
Kutor Labs ("we", "our", or "us") is dedicated to safeguarding user privacy across all of our browser extensions published on the Google Chrome Web Store and Microsoft Edge Add-ons catalog.
This Privacy Policy governs your use of our software products, including but not limited to:
- Position Size & Forex Lot Risk Calculator (
position-size-calculator) - Amazon Quick View & BSR Seller Browser (
amazon-seller-quick-view) - Amazon ASIN Grabber & Fast Exporter (
amazon-asin-grabber) - Amazon Keyword Expander & KDP Search Terms Optimizer (
amazon-keyword-expander) - Amazon Review & Media Exporter + AI VOC Analyzer (
amazon-review-exporter) - Fast CORS Unblocker - Instant API Toggle (
fast-cors-unblocker) - Sound Equalizer, 600% Booster & Normalizer (
sound-eq-booster) - Finviz Screener Exporter & Stock Grabber (
stock-screener-grabber) - Universal Web Table Grabber & Excel Exporter (
universal-table-grabber) - Dual Subtitles - Video Hover Dictionary (
dual-subtitles) - Workday Job Autofill & ATS Resume Assistant (
workday-job-autofill) - Session Restore: Auto Save & Recover Tabs (
session-vault) - Smart Text Expander & Auto-Fill Snippets (
smart-text-expander) - Moa: Web to Figma & Design Inspector (
moa) - Jw Video Looper (
jw-video-looper) - Ecount Quick Report (
ecount-quick-report)
1. Core Privacy Principle: 100% Local-First Processing
All primary application logic, mathematical calculations (e.g. trading position sizing, forex lots, BSR margins, audio equalizing, dual subtitle rendering, text snippet replacement, and DOM data parsing) run 100% locally within your browser's execution memory.
- No Financial Account Tracking: We never collect, store, or transmit your trading account balances, exchange API keys, broker login credentials, trade history, or wallet seed phrases.
- No Browsing History Tracking: We do not monitor, log, or sell your general internet browsing habits or search engine queries.
- No Keystroke Logging or Password Interception: For text expansion and form autofill utilities (Smart Text Expander, Workday Job Autofill), all shortcut matching and profile filling occur 100% locally in browser memory. Sensitive inputs including
type="password", credit card numbers, CVV, and hidden security fields are strictly excluded from inspection. We never log, record, store, or transmit your typed keystrokes, clipboard history, or form values.
2. Information We Collect & Process
A. Anonymous Aggregated Product Analytics (PostHog)
To diagnose technical crashes, monitor feature performance, and ensure service reliability, our extensions collect non-personally identifiable (Zero-PII) telemetry events via PostHog REST Capture:
- Technical Metadata: Browser type (e.g. Chrome, Edge), operating system (macOS, Windows, Linux), screen resolution, and extension version.
- Aggregated Usage Metrics: Feature interaction counts (e.g. calculation button clicked, export format selected, error count).
- Random Anonymous Identifier: A randomly generated client token (
usr_...) stored locally in your browser to calculate daily active usage without identifying the individual user.
B. Voluntary Customer Feedback & Support (Discord Webhook)
When you choose to submit feedback, bug reports, or feature suggestions via the in-app Feedback & VOC panel:
- We receive the text message you write, your optional email address (if provided for direct reply), and basic technical environment details (extension version and OS).
- This data is transmitted securely to our internal team triage channel solely to address your bug report or support inquiry.
C. Pro Licensing & Payment Processing (Dodo Payments)
- Monetization and license fulfillment are powered by Dodo Payments Inc. (our Merchant of Record).
- When purchasing a Pro Lifetime license, your payment information (such as credit card numbers or billing addresses) is processed entirely by Dodo Payments under their strict PCI-DSS compliant security standards.
- Our extensions store only your purchased license activation token locally in
chrome.storageto unlock Pro tier capabilities. We never receive or store your raw payment details. - Extensions marked as 100% Free Forever (e.g. Sound Equalizer) contain zero payment code, zero in-app purchases, and make zero network calls to payment processors.
D. Audio Processing & Media Stream Safety (Sound Equalizer)
For users of Sound Equalizer, 600% Booster & Normalizer, the extension utilizes the standard W3C Web Audio API and Chromium chrome.tabCapture API:
- 100% Ephemeral In-Memory DSP: Audio captured from the active media tab is routed directly through standard Web Audio BiquadFilter (10-band EQ), DynamicsCompressor (normalizer), and soft-knee limiter nodes inside browser memory.
- Zero Audio Recording or Storage: Audio streams are never recorded, captured to disk, or saved to local storage.
- Zero Remote Transmission: No audio waveforms, voice data, or sound packets are ever transmitted across any network or sent to external servers.
- Zero Microphone Access: The extension does NOT request microphone permissions and cannot access user ambient microphones or recording devices.
- Instant Destruction: When the media tab is paused, navigated, or closed, all audio streams and processing contexts are immediately closed and garbage collected.
E. AI Voice of Customer Analysis & Third-Party LLM Safety (Amazon Review Exporter)
For users of Amazon Review & Media Exporter + AI VOC Analyzer, the extension offers optional sentiment analysis powered by Google Gemini (gemini-2.5-flash-lite):
- 100% User-Initiated: AI analysis runs only when the user explicitly clicks "Analyze Reviews with AI". No background or unsolicited requests are made.
- Zero-PII Payload: Only publicly visible product review text snippets are analyzed to extract customer sentiment, pros, and cons. No customer usernames, order numbers, or personal details are included.
- BYOK (Bring Your Own Key) Security: Users may optionally supply their own Google Gemini API key. Custom keys are stored strictly in
chrome.storage.localon the user's machine and are never transmitted to Kutor Labs. - Zero Model Training: Per Google Cloud / Gemini API terms, customer API inputs are not used to train or improve foundational AI models.
F. Video Captions & Real-Time Translation Safety (Dual Subtitles)
For users of Dual Subtitles - Video Hover Dictionary, the extension provides bilingual subtitle overlays and word-by-word hover definitions on streaming video platforms (YouTube, Netflix, Udemy):
- Public Dictionary Queries: Hover translations query Google Translate's public translation endpoint (
https://translate.googleapis.com/*) strictly for the specific word hovered over by the user. - Zero Viewing History Tracking: We never log, track, or transmit the videos you watch, viewing duration, playback timestamps, or learning progress.
- Local Subtitle Synchronization: Subtitle cues and timing alignment operate 100% locally within the browser page DOM.
G. Web Table Scraping & In-Memory Data Processing Safety (Universal Web Table Grabber)
For users of Universal Web Table Grabber & Excel Exporter, the extension detects and extracts HTML table elements (<table>) and structured data grids from web pages:
- 100% Ephemeral In-Memory Processing: All HTML table parsing, 2D matrix normalization (rowspan/colspan unmerging), and spreadsheet formatting (Excel, CSV, TSV) occur strictly within local browser execution memory.
- Zero Table Content or URL Recording: Scraped table cells, headers, numerical figures, and target URLs are never recorded, saved to remote databases, or transmitted across external networks.
- Zero Form Interception or Credential Access: The extension inspects table structures only upon direct user interaction (hover HUD or popup trigger). It never accesses form fields, passwords, cookies, or personal browsing history.
- Instant Garbage Collection: Extracted tabular datasets are discarded from browser memory immediately following the user's export or clipboard copy action.
H. Financial Stock Table Extraction & Screening Data Safety (Finviz Screener Exporter & Stock Grabber)
For users of Finviz Screener Exporter & Stock Grabber, the extension extracts publicly visible financial table data and stock screening grids on supported financial pages (Finviz):
- 100% Ephemeral In-Memory Processing: All table parsing, ticker extraction, numerical metric normalization, and spreadsheet conversions (TSV, Excel, CSV) execute 100% locally in browser memory.
- No Financial Account, Broker, or Portfolio Access: The extension never accesses, inspects, or transmits user trading accounts, broker credentials, order books, personal watchlist holdings, or portfolio balances.
- Zero Scraped Data Storage or Transmission: Scraped stock tickers, prices, P/E ratios, volume, and financial metrics are never transmitted to external servers, logged remotely, or stored in remote databases.
- Instant Destruction: Extracted financial data resides ephemerally in active browser memory and is discarded immediately after export or clipboard copy.
I. Text Expansion & Shortcut Execution Safety (Smart Text Expander)
For users of Smart Text Expander & Auto-Fill Snippets, the extension matches custom keyboard shortcuts and auto-replaces them with user-defined canned responses and dynamic templates:
- 100% Client-Side In-Memory Ring Buffer: Shortcut detection uses a transient, rolling circular buffer in volatile browser memory. Keystroke buffers are analyzed only for matching user triggers and are never saved to disk, recorded, or transmitted to any external server.
- Strict Password Field & Credential Exclusion: The extension strictly excludes and ignores password input fields (
type="password"), credit card inputs, CVV fields, and protected authentication forms. - Local Snippet Vault: All custom shortcuts, snippet templates, dynamic placeholder rules, and domain exclusion blacklists are stored exclusively on your device in
chrome.storage.local. - Zero Keystroke Logging: We never monitor, log, analyze, or transmit your typed keystrokes, clipboard contents, or web form entries.
J. Tab Lifecycle Journaling & Session History Safety (Session Restore)
For users of Session Restore: Auto Save & Recover Tabs (session-vault), the extension records tab lifecycle events into a local event-sourcing continuum timeline for crash recovery and workspace organization:
- 100% Local-First Sandbox Storage: All tab lifecycle events (open, navigate, activate, close), timestamps, titles, and URLs are stored strictly within your local browser sandbox IndexedDB.
- Zero Remote Browsing History Transmission: No tab URLs, web page titles, session notes, window layouts, or browsing histories are ever transmitted across any network or saved to remote databases.
- Memory-Safe Hibernation: Tabs are restored using native browser
discarded: truehibernation APIs, ensuring zero CPU freezing and zero background network requests until the user explicitly clicks the restored tab. - Zero Webpage Interaction: The extension does not request
<all_urls>host permissions, does not inject scripts into user browsing tabs, and never inspects webpage DOM contents, credentials, or form inputs.
3. Permissions Justifications & Least-Privilege Standard
Our extensions adhere strictly to Google Manifest V3 and Microsoft Edge security standards, requesting only the minimal permissions required for their documented functionality:
tabCapture: (Sound Equalizer) Captures the audio stream from the active media tab exclusively to route it through the local 10-band equalizer, 600% volume booster, and volume normalizer Web Audio DSP nodes. Zero audio is ever recorded, stored, or transmitted.offscreen: (Sound Equalizer) Hosts persistent Web Audio Context nodes in Chromium Manifest V3 to prevent audio playback interruption when background service workers enter idle state.declarativeNetRequest: (Fast CORS Unblocker) Used exclusively by developer utilities to inject local debug CORS headers on user-enabled domains without inspecting or intercepting packet contents.storage/unlimitedStorage: (All extensions, Design Inspector, Session Restore) Saves user UI preferences, custom EQ presets, export settings, snippet templates, and offline license tokens locally on your device. Unlimited storage allows Design Inspector to cache design assets locally and Session Restore to store rolling session timeline snapshots and crash recovery history without browser storage quota exhaustion.activeTab: (Most extensions) Allows querying active tab context upon direct user action (e.g. opening side panel, adjusting audio, scanning tables, or copying page data).tabs: (All extensions, Session Restore) Detects active host domains to synchronize extension badge status, side panel states, session management, and audio capture targets. For Session Restore, reads open tab URLs, titles, and favicons to generate timeline snapshots and safely restore tab workspaces.sidePanel: (Most productivity tools) Used to display the persistent tool UI side-by-side with your active tabs (such as trading charts, search pages, or audio equalizers) for continuous workflow efficiency.scripting: (Amazon seller tools, Stock Screener Grabber) Injects local DOM extractor scripts into supported web pages upon direct user action without remote script dependencies.downloads: (Amazon Review Exporter) Allows users to download generated CSV, TSV, or Excel files and customer review media attachments directly to their local download folder upon clicking export.clipboardWrite: (Design Inspector) Copies extracted product ASINs, clean SVG code, CSS markup, or tabular data to the user's system clipboard upon explicit user action.alarms: (Session Restore) Schedules local periodic session cleanups, delta compaction, and rolling snapshot maintenance without external server wakeups.host_permissions:*://*/*: Used exclusively by Sound Equalizer & Booster (to attach Web Audio filters to HTML5<video>and<audio>elements across web pages) and Design Inspector (to extract clean CSS/SVG primitives and perform 11x11 Retina Loupe viewport color sampling on inspected elements). Zero browsing history, cookies, or personal data are collected or transmitted.- Amazon Regional Marketplaces (
*://*.amazon.com/*,*://*.amazon.co.uk/*,*://*.amazon.de/*,*://*.amazon.fr/*,*://*.amazon.it/*,*://*.amazon.es/*,*://*.amazon.co.jp/*,*://*.amazon.ca/*,*://*.amazon.com.au/*,*://*.amazon.com.mx/*,*://*.amazon.in/*): Scoped strictly to supported regional Amazon platforms for Amazon Quick View, ASIN Grabber, Keyword Expander, and Review Exporter to inject seller HUDs and extract publicly visible product data. *://completion.amazon.com/*: Used exclusively by Amazon Keyword Expander to fetch real-time search term suggestions and autocomplete queries directly from Amazon.*://*.media-amazon.com/*,*://*.ssl-images-amazon.com/*: Used exclusively by Amazon Review Exporter to fetch and download customer review photos and video media attachments directly from Amazon CDNs.https://generativelanguage.googleapis.com/*: Used exclusively by Amazon Review Exporter for optional Google Gemini AI Voice-of-Customer sentiment analysis upon explicit user request.https://kutorlabs.com/*,https://www.kutorlabs.com/*: Used for secure AI proxy routing and remote configuration updates.- Streaming Video Platforms (
*://*.youtube.com/*,*://*.netflix.com/*,*://*.udemy.com/*): Used strictly by Dual Subtitles to render dual subtitle DOM overlays and synchronize bilingual subtitle cues during video playback. https://translate.googleapis.com/*: Used exclusively by Dual Subtitles to fetch real-time dictionary definitions and translations directly from Google Translate's public endpoint. Zero queries, viewing history, or vocabulary logs are stored on our servers.- Financial Screening Platforms (
*://*.finviz.com/*,*://finviz.com/*): Scoped strictly to supported financial screening pages for Finviz Screener Exporter & Stock Grabber to extract tabular stock market data upon user click. - ATS Job Application Portals (
https://*.workday.com/*,https://*.myworkdayjobs.com/*,https://boards.greenhouse.io/*,https://job-boards.greenhouse.io/*,https://jobs.lever.co/*): Scoped strictly to supported job application forms for Workday Job Autofill to detect form fields and autofill saved applicant profile data. - ECOUNT ERP Cloud & Open API (
*://*.ecount.com/*,*://sboapi*.ecount.com/*,*://oapi*.ecount.com/*): Scoped strictly to ECOUNT ERP portals and official Open API endpoints for Quick Report for ECOUNT ERP to query sales summaries, inventory balances, and inject the one-click executive dashboard HUD. *://*.dodopayments.com/*: Strictly limited to verifying purchase completion and activating Pro licenses.
4. Third-Party Sharing & Data Sales Prohibition
- Zero Data Sales: We do NOT sell, rent, or monetize your data under any circumstances.
- Zero Third-Party Advertising Trackers: We do not embed ad networks, tracking pixels, or third-party behavioral profiling scripts in our extensions.
- No Remote Code Execution: All JavaScript and UI components are statically bundled inside the extension package. We execute zero remote scripts or dynamic
eval()code.
5. Contact Information & Data Deletion Requests
If you have any questions about this Privacy Policy, or wish to request the deletion of any voluntary support correspondence, please contact us:
- Company / Developer: Kutor Labs
- Support Email:
[email protected] - Website:
https://kutorlabs.com - Privacy Portal:
https://kutorlabs.com/privacy